Washington A.G. Ferguson's Investigation Into Premera Data Breach Results in Premera Paying $10 Million Over Failure to Protect Sensitive Patient Data - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
July 12, 2019 Newswires
Share
Share
Tweet
Email

Washington A.G. Ferguson’s Investigation Into Premera Data Breach Results in Premera Paying $10 Million Over Failure to Protect Sensitive Patient Data

Targeted News Service (Press Releases)

OLYMPIA, Washington, July 11 -- Washington state Attorney General Bob Ferguson issued the following news release:

* * *

- Premera will pay $5.4 million to Washington and another $4.6 million to coalition of 29 state attorneys general that joined Ferguson's investigation

* * *

As a result of an Attorney General's Office investigation, Premera Blue Cross, the largest health insurance company in the Pacific Northwest, will pay $10 million nationwide for failing to secure sensitive consumer data and for misleading consumers before and after a data breach affecting millions across the country. Attorney General Bob Ferguson led a coalition of 30 state attorneys general investigating the company's practices.

The data breach affected the information of more than 10.4 million individuals nationwide, including more than 6.4 million Washingtonians. Under the consent decree, filed today in Snohomish County Superior Court, Premera will pay $5.4 million of the total recovery to the Washington State Attorney General's Office, which will go towards continued enforcement of state data security and privacy laws, and nearly $4.6 million to the coalition of states that joined Ferguson's legal action.

Premera's $10 million payment to the states is in addition to any payment from the proposed class action settlement, which was filed in federal court in Oregon but not yet finalized by the court.

The consent decree also legally requires Premera to implement specific data security controls to protect personal health information, annually review its security practices and provide data security reports to the Washington State Attorney General's Office.

"Premera had an obligation to safeguard the privacy of millions of Washingtonians -- and failed," Ferguson said. "As a result, millions had their sensitive information exposed. Premera repeatedly ignored both its own employees and cybersecurity experts who warned millions of consumers' sensitive health information was at risk."

In today's complaint, Ferguson asserts that the company failed to meet its obligations under the federal Health Insurance Portability and Accountability Act (HIPAA) and violated the Washington State Consumer Protection Act by not addressing known cybersecurity vulnerabilities that gave a hacker access to protected health information for almost a year.

From May 5, 2014 until March 6, 2015, a hacker had unauthorized access to the Premera network containing sensitive personal information, including private health information, Social Security numbers, bank account information, names, addresses, phone numbers, dates of birth, member identification numbers and email addresses.

The hacker took advantage of multiple known weaknesses in Premera's data security. For years prior to the breach, cybersecurity experts and the company's own auditors repeatedly warned Premera of its inadequate security program, yet the company accepted many of the risks without fixing its practices.

Ferguson's complaint asserts that Premera misled Washingtonians and other consumers nationwide about its privacy practices before and after the data breach. In privacy notices, Premera told its members, "We take steps to secure our buildings and electronic systems from unauthorized access."

After the breach became public, Premera's call center agents told consumers there was "no reason to believe that any of your information was accessed or misused." They also told consumers that "there were already significant security measures in place to protect your information," even though multiple security experts and auditors warned the company of its security vulnerabilities prior to the breach.

Under HIPAA, Premera is required to implement administrative, physical and technical safeguards that reasonably and appropriately protect sensitive consumer information. Premera repeatedly failed to meet these standards, leaving millions of consumer's sensitive data vulnerable to hackers for nearly a year.

Today's consent decree also requires Premera to:

* Ensure its data security program protects personal health information as required by law

* Regularly assess and update its security measures

* Map where HIPAA-protected information, including personal health information, is located on the Premera network

* Provide data security reports, completed by a third-party security expert approved by the multistate coalition, to the Washington State Attorney General's Office

* Hire a chief information security officer, a separate position from the chief information officer. The information security officer must be experienced in data security and HIPAA compliance and will be responsible for implementing, maintaining and monitoring the company's security program.

* Hold regular meetings between the chief information security officer and Premera's executive management. The information security officer must meet with Premera's CEO every two months and inform the CEO of any unauthorized intrusion into the Premera network within 48 hours of discovery.

* Create a compliance program and hire a compliance officer with a background in HIPAA compliance

* Map where HIPAA-protected information, including personal health information, is located on the Premera network

* Provide security training to all employees who handle personal information and protected health information

The proposed class action settlement provides for additional relief for affected individuals. Consumers affected by Premera's conduct should expect to receive information about restitution after the settlement is approved by the court. More information about the class action is available here.

Joining Washington are Alabama, Alaska, Arizona, Arkansas, California, Connecticut, Florida, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Massachusetts, Minnesota, Mississippi, Montana, Nebraska, Nevada, New Jersey, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Rhode Island, Utah and Vermont.

Assistant Attorneys General Tiffany Lee, Andrea Alegrett, and Lynda Atkins, along with Senior Investigator Rebecca Hartsock, are leading the case for Washington.

Older

Insurance Information Institute Offers Guidance to Texans, Louisianans As Tropical Storm Barry Approaches

Newer

Louisiana Gov. Edwards Request Federal Emergency Declaration in Advance of Tropical Storm Barry

Advisor News

  • Affordability on Florida lawmakers’ minds as they return to the state Capitol
  • Gen X confident in investment decisions, despite having no plan
  • Most Americans optimistic about a financial ‘resolution rebound’ in 2026
  • Mitigating recession-based client anxiety
  • Terri Kallsen begins board chair role at CFP Board
More Advisor News

Annuity News

  • Reframing lifetime income as an essential part of retirement planning
  • Integrity adds further scale with blockbuster acquisition of AIMCOR
  • MetLife Declares First Quarter 2026 Common Stock Dividend
  • Using annuities as a legacy tool: The ROP feature
  • Jackson Financial Inc. and TPG Inc. Announce Long-Term Strategic Partnership
More Annuity News

Health/Employee Benefits News

  • In Snohomish County, new year brings changes to health insurance
  • Visitor Guard® Unveils 2026 Visitor Insurance Guide for Families, Seniors, and Students Traveling to the US
  • UCare CEO salary topped $1M as the health insurer foundered
  • Va. Republicans split over extending Va. Republicans split over extending health care subsidies
  • Governor's proposed budget includes fully funding Medicaid and lowering cost of kynect coverage
More Health/Employee Benefits News

Life Insurance News

  • Best's Review Looks at What’s Next in 2026
  • Life insurance application activity ends 2025 with record growth, MIB reports
  • Vermont judge sides with National Life on IUL illustrations lawsuit
  • AM Best Affirms Credit Ratings of Insignia Life S.A. de C.V.
  • Whole life or IUL? Help clients to choose what’s best for them
Sponsor
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

8.25% Cap Guaranteed for the Full Term
Guaranteed cap rate for 5 & 7 years—no annual resets. Explore Oceanview CapLock FIA.

Press Releases

  • Two industry finance experts join National Life Group amid accelerated growth
  • National Life Group Announces Leadership Transition at Equity Services, Inc.
  • SandStone Insurance Partners Welcomes Industry Veteran, Rhonda Waskie, as Senior Account Executive
  • Springline Advisory Announces Partnership With Software And Consulting Firm Actuarial Resources Corporation
  • Insuraviews Closes New Funding Round Led by Idea Fund to Scale Market Intelligence Platform
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet